RabbitMQ SSL端口5671可telnet但EasyNetQ连接失败求助
Let’s walk through the key issues in your code and setup that are almost certainly causing this connection failure, plus how to fix them step by step:
1. SSL Server Name Mismatch is a Critical Red Flag
Your code sets host1.Ssl.ServerName = "localhost"; — that’s incorrect. The SSL Server Name has to exactly match the Common Name (CN) or Subject Alternative Name (SAN) on the RabbitMQ server’s certificate. Since you’re connecting to skl-igor-naum1, this value needs to be that hostname (or whatever CN/SAN is listed on the server’s cert). If the server cert was issued to skl-igor-naum1, update this line to:
host1.Ssl.ServerName = "skl-igor-naum1";
A mismatch here breaks the SSL handshake entirely, which shows up as the vague "unreachable endpoints" error in EasyNetQ.
2. Don’t Skip the Certificate Passphrase (If Your PFX Has One)
You commented out host1.Ssl.CertPassphrase = "admin"; — if your .pfx file is password-protected (which 99% of production certificates are), you must uncomment this and use the correct password. Without it, the client can’t load the certificate, and the connection will fail silently (or with that unhelpful unreachable message).
3. Enforce a Modern TLS Version
RabbitMQ usually blocks older TLS versions like 1.0 or 1.1 by default for security. Uncomment and set the SSL version to TLS 1.2 (the minimum recommended for secure connections):
host1.Ssl.Version = System.Security.Authentication.SslProtocols.Tls12;
Stick to TLS 1.2 or higher unless your server is explicitly configured to allow older versions (you shouldn’t be using those anyway for compliance with security standards).
4. Clean Up Redundant Port Settings
You set connection.Port = 5671; and host1.Port = 5671; — this isn’t breaking anything, but it’s redundant. You can remove the top-level connection.Port line since you’re already defining the port in the HostConfiguration.
5. Double-Check Certificate Trust and File Access
Make sure:
- The path
C:\\tmp\\ProfileUnity.pfxis correct, and your application has read access to that file (if it’s running as a service, it might need explicit permissions to thetmpfolder). - The RabbitMQ server’s certificate is installed in the Trusted Root Certification Authorities store on your client machine (not just the Current User store, if your app runs under a system account).
- If your RabbitMQ setup requires mutual TLS (client certificate authentication), ensure your client cert is trusted by the server and has the right permissions.
Corrected Code Example
Here’s your code with all the key fixes applied:
var connection = new ConnectionConfiguration(); connection.UserName = "admin"; connection.Password = "****"; connection.Product = "YourClientAppName"; // Update this to your actual app name, not "localhost" connection.VirtualHost = "StageDev"; var host1 = new HostConfiguration(); host1.Host = "skl-igor-naum1"; host1.Port = 5671; host1.Ssl.Enabled = true; host1.Ssl.ServerName = "skl-igor-naum1"; // Matches server cert CN/SAN host1.Ssl.CertPath = "C:\\tmp\\ProfileUnity.pfx"; host1.Ssl.CertPassphrase = "admin"; // Uncommented with correct password host1.Ssl.Version = System.Security.Authentication.SslProtocols.Tls12; // Enforce secure TLS connection.Hosts = new List<HostConfiguration> { host1 }; connection.Validate(); MessageBusConnection = RabbitHutch.CreateBus(connection, services => services.Register<IEasyNetQLogger>(logger => new DoNothingLogger()));
Extra Debugging Tips If You’re Still Stuck
- Enable proper logging: Replace
DoNothingLoggerwith a logger that outputs debug details (like the built-inConsoleLogger). This will show you the actual SSL handshake error, which is way more useful than the vague "unreachable" message. - Test TLS with openssl: Run
openssl s_client -connect skl-igor-naum1:5671from your client machine. If this fails, the issue is with TLS setup, not your code. - Check RabbitMQ server logs: Look for TLS-related errors in the server logs when your client tries to connect — it might tell you exactly what’s wrong (like invalid client cert, mismatched CN, etc.).
内容的提问来源于stack exchange,提问作者user434774

